Vulnerability Name:

CVE-2007-4632 (CCN-36477)

Assigned:2007-08-29
Published:2007-08-29
Updated:2018-10-26
Summary:Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.
CVSS v3 Severity:5.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Adjacent
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2007-4632

Source: CISCO
Type: Patch, Vendor Advisory
20070829 VTY Authentication Bypass Vulnerability

Source: CCN
Type: cisco-sr-20070829-vty
VTY Authentication Bypass Vulnerability

Source: CCN
Type: NileSOFT Security Advisory NILESA-20070731
Bypass Authentication Vulnerability on Cisco Catalyst 3750 12.2(25)

Source: BID
Type: Third Party Advisory, VDB Entry
25482

Source: CCN
Type: BID-25482
Cisco IOS VTY Authentication Bypass Vulnerability

Source: XF
Type: UNKNOWN
cisco-catalyst-vty-authentication-bypass(36477)

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:5866

Vulnerable Configuration:Configuration 1:
  • cpe:/o:cisco:ios:12.2e:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2f:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2s:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:cisco:ios:12.2s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2ew:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2se:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sv:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sw:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sz:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2ewa:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sxd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2eu:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2ex:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sea:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2ey:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2fx:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sbc:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sg:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sxe:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sed:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2see:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2seg:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2e:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2f:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2fy:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:5866
    V
    Cisco IOS VTY Authentication Bypass Vulnerability
    2008-09-08
    BACK
    cisco ios 12.2e
    cisco ios 12.2f
    cisco ios 12.2s
    cisco ios 12.2s
    cisco ios 12.2ew
    cisco ios 12.2se
    cisco ios 12.2sv
    cisco ios 12.2sw
    cisco ios 12.2sz
    cisco ios 12.2ewa
    cisco ios 12.2sxd
    cisco ios 12.2eu
    cisco ios 12.2ex
    cisco ios 12.2sea
    cisco ios 12.2ey
    cisco ios 12.2fx
    cisco ios 12.2sbc
    cisco ios 12.2sg
    cisco ios 12.2sxe
    cisco ios 12.2sed
    cisco ios 12.2see
    cisco ios 12.2seg
    cisco ios 12.2e
    cisco ios 12.2f
    cisco ios 12.2fy